AWS Logging & Audit Foundation
A record of who did what, kept long enough to be useful and somewhere it cannot be edited.
From $299 2–4 days
The technical controls a HIPAA workload needs on AWS, built and documented. Not a certification.
From $1,149
Typically $1,149–$3,499, fixed in writing before anything starts.
What moves it up
The Business Associate Addendum gets signed and people relax, because AWS is now "HIPAA compliant". What the BAA actually does is permit protected health information on a defined list of eligible services — it makes nothing compliant on its own, and using an ineligible service puts you outside it without any warning from the console. Underneath that, the controls that fail a review are always the same ones: encryption in transit between internal services rather than only at the edge, an audit trail of who accessed a record rather than who changed infrastructure, and backups that are encrypted but not access-controlled separately from production.
Every service in the architecture checked against the current AWS HIPAA eligible services listaws kms list-keys and describe-key — customer-managed keys with rotation, or the AWS-managed defaultaws rds describe-db-instances --query 'DBInstances[].[StorageEncrypted,PubliclyAccessible]'Application-level access logging, which is where record-level access lives and infrastructure logs do not reachNo, and be careful with anyone who says otherwise. HIPAA compliance covers policies, training, agreements and risk assessments as well as technology. This builds and documents the technical safeguards, which is a substantial part of it and not the whole. I am an engineer, not your compliance officer or your lawyer.
You need one, it is free, and you accept it in Artifact. It permits protected health information on AWS's list of eligible services. It does not make your architecture compliant, and nothing stops you using an ineligible service after signing it — which is one of the first things this engagement checks.
Yes, and it is the normal case. It costs more than building clean because some changes — encrypting an unencrypted database, moving a subnet — require a maintenance window and a migration rather than a setting. Those are identified and scheduled rather than discovered halfway.
The technical sections, largely — that is what the control mapping is for, so each answer points at something real rather than a claim. Questions about your policies, your staff training and your incident process are yours to answer, and no infrastructure work will do it for you.
A record of who did what, kept long enough to be useful and somewhere it cannot be edited.
From $299 2–4 days
Backups covering everything that matters, and one of them restored and timed in front of you.
From $449 2–5 days
Tell me what you are running and I will come back with a fixed price and a date. If it turns out you do not need this, I will say that instead.
Prefer to talk? Book a free call ↗ · Or hire me on Upwork ↗ · Typical reply within one business day.
Sunday to Thursday, 09:00–18:00 EET. Outside that I will still look, but I will not promise a time.
One person, one time zone. If round-the-clock cover is what you need, you need a team, and I will say so rather than sell you a plan that cannot deliver it.
You pay Amazon directly and you keep control of the account. Nothing here resells your infrastructure or sits between you and your own billing.
Every service page lists exactly what pushes a quote above it, before you ask. You get a fixed number in writing before any work begins.